Home Private Messages Search
CPG Dragonfly™ CMS stopsoftwarepatents.eu petition banner
Toggle Content
 
Forums ⇒ CMS (All) ⇒ Security :: Archives ⇒ phpinfo :: Archived


phpinfo :: Archived
Post any security related questions in here.
Please send discovered reports to security @ cpgnuke.com
Do Not post links to exploits or hacker sites - your post will be edited/deleted.
If you think you've been hacked, FIRST go through your server logs.

Post new topic    Revive this topic    Printer Friendly Page     Forum Index ⇒  Security

Topic Archived View previous topic :: View next topic  
Author Message
sharkey
Supporter
Supporter

Offline Offline
Joined: May 05, 2004
Posts: 116

PostPosted: Wed Jul 21, 2004 6:17 am
Post subject: phpinfo

Is leaving phpinfo available dangerous?

I'm specifically refering to these fields:

_REQUEST["nuke_cpg_nuke_data"]

_REQUEST["user"]

_SERVER["HTTP_COOKIE"]

Do these only show the info from the browser looking or could someone use those fields to hijack a session?

Also this one would be scary but it's blank so it's cool

mysql.default_password no value no value

_________________
DragonFly 9.0.3.0

sharkey's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/1.1.31/4.0.20-standard/4.3.8/8.2b
Back to top
View user's profile
xfsunoles
XHTML Specialist
XHTML Specialist

Offline Offline
Joined: Apr 30, 2004
Posts: 2502
Location: Melbourne, Florida
PostPosted: Wed Jul 21, 2004 6:32 am
Post subject: Re: phpinfo

sharkey wrote:
Is leaving phpinfo available dangerous?

I'm specifically refering to these fields:

_REQUEST["nuke_cpg_nuke_data"]

_REQUEST["user"]

_SERVER["HTTP_COOKIE"]

Do these only show the info from the browser looking or could someone use those fields to hijack a session?

Also this one would be scary but it's blank so it's cool

mysql.default_password no value no value
your first question is yes it can show the path and other server varibles that an attacker can use

_________________

Firefox is my Favorite Browser

xfsunoles's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Apache/1.3.34 (Unix)/4.0.25-standard/4.4.1/CVS
Back to top
View user's profile Visit poster's website AIM Address MSN Messenger Yahoo Messenger Photo Gallery
Display posts from previous:   
Post new topic    Revive this topic    Printer Friendly Page    Forum Index ⇒  Security
Page 1 of 1
All times are GMT

Archive Revive
Username:
This is an archived topic - your reply will not be appended here.
Instead, a new topic will be generated in the active forum.
The new topic will provide a reference link to this archived topic.
 
   Toggle Content User Info

Welcome Anonymous

Nickname
Password
(Register)

   Toggle Content Last CVS commits
· Fixed .ico Expires header.
· Removed domain name from cookies so subdomains wont access them anymore.
· CSS and JS, case insensitives.
· CSS and JS, send correct HTTP 1.1 headers and fixed issues where themes and...
· Further security class improvements.
· 301 redirects on LEO changes
· Option to force 3xx http status codes
· Validate googlebot.com and google.com crawlers.
· CCBot
· Rss with etag and atom.

อ่านต่อ...

   Toggle Content Community

Support for DragonflyCMS in a other languages:

Deutsch
Español

   Toggle Content X-links
UltraEdit Browse Happy logo Firefox MySQL PostgreSQL Valid CSS! Valid XHTML 1.0! Unicode Encoded Badge NukeBiz Resources Raven DragonflyCMS Dedicated Now InsideSupport Lampe Berger

You are seeing squares or questionmarks on this page?

All content of this website is copyrighted by the Creative Commons NC-SA
The logos and trademarks used on this site are the property of their respective owners
We are not responsible for comments posted by our users, as they are the property of the poster.
Our server runs on a P3 1.2GHz with 512MB RAM with no accelerators
Support GoPHP5.org
Interactive software released under GNU GPL, Code Credits, Privacy Policy